Advertisement
Guest User

fixlog -frst

a guest
Mar 5th, 2016
201
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 12.51 KB | None | 0 0
  1. Fix result of Farbar Recovery Scan Tool (x64) Version:04-03-2016
  2. Ran by Petr (2016-03-05 20:29:48) Run:1
  3. Running from C:\Users\Petr\Desktop
  4. Loaded Profiles: Petr (Available Profiles: Petr)
  5. Boot Mode: Normal
  6. ==============================================
  7.  
  8. fixlist content:
  9. *****************
  10. Start
  11. CreateRestorePoint:
  12. CloseProcesses:
  13.  
  14. Task: {1F96EC9C-6291-4C2C-9B2A-6AF2B3AD6000} - System32\Tasks\WINshell Event Notification => C:\Users\KONTRA~1\AppData\Local\Temp\SBCint2.exe <==== ATTENTION
  15. Task: {C7701396-3622-4FA8-91F0-05421ADFB614} - \Update\cryptex -> No File <==== ATTENTION
  16. Task: {E954E6AE-695F-4BC8-BA0D-901CAC10C3D8} - System32\Tasks\WINshell Event Logging => C:\Users\KONTRA~1\AppData\Local\Temp\Dscp1.exe <==== ATTENTION
  17.  
  18. HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-06] (Apple Inc.)
  19. HKLM\...\Policies\Explorer: [HideSCAHealth] 1
  20. HKU\S-1-5-21-3631145020-3224763176-4093947856-1001\...\MountPoints2: {fbdf364a-e361-11e4-9eee-806e6f6e6963} - D:\Autorun.exe
  21. HKU\S-1-5-18\...\Policies\Explorer: [HideSCAHealth] 1
  22. S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
  23. Folder: C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
  24.  
  25. EmptyTemp:
  26. REG: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
  27. REG: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
  28. RemoveProxy:
  29. CMD: bitsadmin /reset /allusers
  30. CMD: netsh advfirewall reset
  31. CMD: netsh advfirewall set allprofiles state ON
  32. CMD: ipconfig /flushdns
  33. CMD: netsh winsock reset catalog
  34. CMD: netsh int ip reset c:\resetlog.txt
  35. CMD: ipconfig /release
  36. CMD: ipconfig /renew
  37. CMD: netsh int ipv4 reset
  38. CMD: netsh int ipv6 reset
  39. CMD: msiexec /unreg
  40. CMD: msiexec /regserver
  41. CMD: winmgmt /verifyrepository
  42. REG: reg delete HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg /f
  43. REG: reg add HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg /f
  44. End
  45. *****************
  46.  
  47. Error: (0) Failed to create a restore point.
  48. Processes closed successfully.
  49. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1F96EC9C-6291-4C2C-9B2A-6AF2B3AD6000}" => key removed successfully
  50. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1F96EC9C-6291-4C2C-9B2A-6AF2B3AD6000}" => key removed successfully
  51. C:\Windows\System32\Tasks\WINshell Event Notification => moved successfully
  52. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WINshell Event Notification" => key removed successfully
  53. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C7701396-3622-4FA8-91F0-05421ADFB614}" => key removed successfully
  54. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C7701396-3622-4FA8-91F0-05421ADFB614}" => key removed successfully
  55. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\cryptex" => key removed successfully
  56. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E954E6AE-695F-4BC8-BA0D-901CAC10C3D8}" => key removed successfully
  57. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E954E6AE-695F-4BC8-BA0D-901CAC10C3D8}" => key removed successfully
  58. C:\Windows\System32\Tasks\WINshell Event Logging => moved successfully
  59. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WINshell Event Logging" => key removed successfully
  60. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper => value removed successfully
  61. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => value removed successfully
  62. "HKU\S-1-5-21-3631145020-3224763176-4093947856-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fbdf364a-e361-11e4-9eee-806e6f6e6963}" => key removed successfully
  63. HKCR\CLSID\{fbdf364a-e361-11e4-9eee-806e6f6e6963} => key not found.
  64. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => value removed successfully
  65. xhunter1 => service removed successfully
  66.  
  67. ========================= Folder: C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 ========================
  68.  
  69. 2012-10-08 16:19 - 2012-10-08 16:19 - 1977816 _____ (GEAR Software, Inc.) C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\GEARDIFx.exe
  70. 2016-03-03 21:41 - 2016-03-03 21:41 - 0000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64
  71. 2012-10-03 16:14 - 2012-10-03 16:14 - 0519048 _____ (Microsoft Corporation) C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\DIFxAPI.dll
  72. 2012-10-08 16:19 - 2012-10-08 16:19 - 0131544 _____ (GEAR Software, Inc.) C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\DifXInst64.exe
  73. 2016-03-03 21:41 - 2016-03-03 21:41 - 0004842 _____ () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\DIFxInstallLog.txt
  74. 2012-10-03 16:14 - 2012-10-03 16:14 - 0106928 _____ (GEAR Software Inc.) C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\GEARAspi.dll
  75. 2012-10-03 16:14 - 2012-10-03 16:14 - 0125872 _____ (GEAR Software Inc.) C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\GEARAspi64.dll
  76. 2012-10-03 16:14 - 2012-10-03 16:14 - 0002561 _____ () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\GEARAspiWDM.inf
  77. 2012-10-03 16:14 - 2012-10-03 16:14 - 0007638 _____ () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\gearaspiwdmx64.cat
  78. 2016-03-03 21:41 - 2016-03-03 21:41 - 0000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\x64
  79. 2012-10-03 16:14 - 2012-10-03 16:14 - 0033240 _____ (GEAR Software Inc.) C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\x64\GEARAspiWDM.sys
  80.  
  81. ====== End of Folder: ======
  82.  
  83.  
  84. ========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
  85.  
  86. Operace byla dokonźena ŁspŘçnŘ.
  87.  
  88.  
  89.  
  90. ========= End of Reg: =========
  91.  
  92.  
  93. ========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
  94.  
  95. Operace byla dokonźena ŁspŘçnŘ.
  96.  
  97.  
  98.  
  99. ========= End of Reg: =========
  100.  
  101.  
  102. ========= RemoveProxy: =========
  103.  
  104. HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
  105. HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
  106. HKU\S-1-5-21-3631145020-3224763176-4093947856-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
  107. HKU\S-1-5-21-3631145020-3224763176-4093947856-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
  108.  
  109.  
  110. ========= End of RemoveProxy: =========
  111.  
  112.  
  113. ========= bitsadmin /reset /allusers =========
  114.  
  115.  
  116. BITSADMIN version 3.0 [ 7.5.7601 ]
  117. BITS administration utility.
  118. (C) Copyright 2000-2006 Microsoft Corp.
  119.  
  120. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
  121. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
  122.  
  123. {D0B0AD65-DBEF-4DDF-B869-4BC5F0B97E0A} canceled.
  124. {72B08334-34DB-46AF-B0EE-8027F107FD37} canceled.
  125. {95E4B6E9-BA42-4ABE-BC4E-0DE9BE75E18D} canceled.
  126. 3 out of 3 jobs canceled.
  127.  
  128. ========= End of CMD: =========
  129.  
  130.  
  131. ========= netsh advfirewall reset =========
  132.  
  133. OK.
  134.  
  135.  
  136. ========= End of CMD: =========
  137.  
  138.  
  139. ========= netsh advfirewall set allprofiles state ON =========
  140.  
  141. OK.
  142.  
  143.  
  144. ========= End of CMD: =========
  145.  
  146.  
  147. ========= ipconfig /flushdns =========
  148.  
  149.  
  150. Konfigurace protokolu IP syst�mu Windows
  151.  
  152. Mezipam؜ p�ekl�d�n� DNS byla �sp��n� vypr�zdn�na.
  153.  
  154. ========= End of CMD: =========
  155.  
  156.  
  157. ========= netsh winsock reset catalog =========
  158.  
  159.  
  160. Katalog Winsock byl �sp��n� resetov�n.
  161. K dokon�en� resetov�n� je nutn� restartovat po��ta�.
  162.  
  163.  
  164. ========= End of CMD: =========
  165.  
  166.  
  167. ========= netsh int ip reset c:\resetlog.txt =========
  168.  
  169. �sp��n� resetov�n� Glob�ln�.
  170. �sp��n� resetov�n� Rozhran�.
  171. �sp��n� resetov�n� Trasa.
  172. K dokon�en� t�to akce restartujte po��ta�.
  173.  
  174.  
  175. ========= End of CMD: =========
  176.  
  177.  
  178. ========= ipconfig /release =========
  179.  
  180.  
  181. Konfigurace protokolu IP syst�mu Windows
  182.  
  183. Na za��zen� P�ipojen� k m�stn� s�ti nelze prov�st ��dnou operaci, dokud je m�dium tohoto
  184. za��zen� odpojeno.
  185.  
  186. Adapt�r bezdr�tov� s�t� LAN Bezdr�tov� p�ipojen� k s�ti:
  187.  
  188. P��pona DNS podle p�ipojen� . . . :
  189. M�stn� IPv6 adresa v r�mci propojen� . . . : fe80::8c2:1db3:d974:8ac9%17
  190. V�choz� br�na . . . . . . . . . . :
  191.  
  192. Adapt�r s�t� Ethernet P�ipojen� k m�stn� s�ti:
  193.  
  194. Stav m�dia . . . . . . . . . . . : odpojeno
  195. P��pona DNS podle p�ipojen� . . . :
  196.  
  197. Adapt�r s�t� Ethernet Hamachi:
  198.  
  199. P��pona DNS podle p�ipojen� . . . :
  200. IPv6 adresa. . . . . . . . . . . : 2620:9b::1975:7c7d
  201. M�stn� IPv6 adresa v r�mci propojen� . . . : fe80::47e:2a5c:2128:b575%13
  202. V�choz� br�na . . . . . . . . . . : 2620:9b::1900:1
  203. 25.0.0.1
  204.  
  205. Adapt�r pro tunelov� p�ipojen� isatap.{5557C01E-2738-43D3-AABF-52B95E72C202}:
  206.  
  207. Stav m�dia . . . . . . . . . . . : odpojeno
  208. P��pona DNS podle p�ipojen� . . . :
  209.  
  210. Adapt�r pro tunelov� p�ipojen� Teredo Tunneling Pseudo-Interface:
  211.  
  212. Stav m�dia . . . . . . . . . . . : odpojeno
  213. P��pona DNS podle p�ipojen� . . . :
  214.  
  215. Adapt�r pro tunelov� p�ipojen� isatap.{E2E70730-0B10-443D-B14E-6D86DB7C0894}:
  216.  
  217. Stav m�dia . . . . . . . . . . . : odpojeno
  218. P��pona DNS podle p�ipojen� . . . :
  219.  
  220. ========= End of CMD: =========
  221.  
  222.  
  223. ========= ipconfig /renew =========
  224.  
  225.  
  226. Konfigurace protokolu IP syst�mu Windows
  227.  
  228. Na za��zen� P�ipojen� k m�stn� s�ti nelze prov�st ��dnou operaci, dokud je m�dium tohoto
  229. za��zen� odpojeno.
  230.  
  231. Adapt�r bezdr�tov� s�t� LAN Bezdr�tov� p�ipojen� k s�ti:
  232.  
  233. P��pona DNS podle p�ipojen� . . . :
  234. M�stn� IPv6 adresa v r�mci propojen� . . . : fe80::8c2:1db3:d974:8ac9%17
  235. Adresa IPv4 . . . . . . . . . . . : 10.0.0.3
  236. Maska pods�t� . . . . . . . . . . : 255.255.255.0
  237. V�choz� br�na . . . . . . . . . . : 10.0.0.138
  238.  
  239. Adapt�r s�t� Ethernet P�ipojen� k m�stn� s�ti:
  240.  
  241. Stav m�dia . . . . . . . . . . . : odpojeno
  242. P��pona DNS podle p�ipojen� . . . :
  243.  
  244. Adapt�r s�t� Ethernet Hamachi:
  245.  
  246. P��pona DNS podle p�ipojen� . . . :
  247. IPv6 adresa. . . . . . . . . . . : 2620:9b::1975:7c7d
  248. M�stn� IPv6 adresa v r�mci propojen� . . . : fe80::47e:2a5c:2128:b575%13
  249. Adresa IPv4 . . . . . . . . . . . : 25.117.124.125
  250. Maska pods�t� . . . . . . . . . . : 255.0.0.0
  251. V�choz� br�na . . . . . . . . . . : 2620:9b::1900:1
  252. 25.0.0.1
  253.  
  254. Adapt�r pro tunelov� p�ipojen� isatap.{5557C01E-2738-43D3-AABF-52B95E72C202}:
  255.  
  256. Stav m�dia . . . . . . . . . . . : odpojeno
  257. P��pona DNS podle p�ipojen� . . . :
  258.  
  259. Adapt�r pro tunelov� p�ipojen� Teredo Tunneling Pseudo-Interface:
  260.  
  261. Stav m�dia . . . . . . . . . . . : odpojeno
  262. P��pona DNS podle p�ipojen� . . . :
  263.  
  264. ========= End of CMD: =========
  265.  
  266.  
  267. ========= netsh int ipv4 reset =========
  268.  
  269. �sp��n� resetov�n� Rozhran�.
  270. K dokon�en� t�to akce restartujte po��ta�.
  271.  
  272.  
  273. ========= End of CMD: =========
  274.  
  275.  
  276. ========= netsh int ipv6 reset =========
  277.  
  278. �sp��n� resetov�n� Rozhran�.
  279. �sp��n� resetov�n� Adresa jednosm�rov�ho vys�l�n�.
  280. �sp��n� resetov�n� Trasa.
  281. K dokon�en� t�to akce restartujte po��ta�.
  282.  
  283.  
  284. ========= End of CMD: =========
  285.  
  286.  
  287. ========= msiexec /unreg =========
  288.  
  289.  
  290. ========= End of CMD: =========
  291.  
  292.  
  293. ========= msiexec /regserver =========
  294.  
  295.  
  296. ========= End of CMD: =========
  297.  
  298.  
  299. ========= winmgmt /verifyrepository =========
  300.  
  301. �lo�i�t� slu�by WMI je konzistentn�.
  302.  
  303. ========= End of CMD: =========
  304.  
  305.  
  306. ========= reg delete HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg /f =========
  307.  
  308. CHYBA: Neplatn  syntaxe.
  309. Chcete-li zobrazit n povŘdu, zadejte pýˇkaz REG DELETE /?.
  310.  
  311.  
  312. ========= End of Reg: =========
  313.  
  314.  
  315. ========= reg add HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg /f =========
  316.  
  317. CHYBA: Neplatn  syntaxe.
  318. Chcete-li zobrazit n povŘdu, zadejte pýˇkaz REG ADD /?.
  319.  
  320.  
  321. ========= End of Reg: =========
  322.  
  323. EmptyTemp: => 1.2 GB temporary data Removed.
  324.  
  325.  
  326. The system needed a reboot.
  327.  
  328. ==== End of Fixlog 20:30:24 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement